1*c40a6cd7SToomas Soome /*
2f9fbec18Smcpowers  * ***** BEGIN LICENSE BLOCK *****
3f9fbec18Smcpowers  * Version: MPL 1.1/GPL 2.0/LGPL 2.1
4f9fbec18Smcpowers  *
5f9fbec18Smcpowers  * The contents of this file are subject to the Mozilla Public License Version
6f9fbec18Smcpowers  * 1.1 (the "License"); you may not use this file except in compliance with
7f9fbec18Smcpowers  * the License. You may obtain a copy of the License at
8f9fbec18Smcpowers  * http://www.mozilla.org/MPL/
9f9fbec18Smcpowers  *
10f9fbec18Smcpowers  * Software distributed under the License is distributed on an "AS IS" basis,
11f9fbec18Smcpowers  * WITHOUT WARRANTY OF ANY KIND, either express or implied. See the License
12f9fbec18Smcpowers  * for the specific language governing rights and limitations under the
13f9fbec18Smcpowers  * License.
14f9fbec18Smcpowers  *
15f9fbec18Smcpowers  * The Original Code is the elliptic curve math library for prime field curves.
16f9fbec18Smcpowers  *
17f9fbec18Smcpowers  * The Initial Developer of the Original Code is
18f9fbec18Smcpowers  * Sun Microsystems, Inc.
19f9fbec18Smcpowers  * Portions created by the Initial Developer are Copyright (C) 2003
20f9fbec18Smcpowers  * the Initial Developer. All Rights Reserved.
21f9fbec18Smcpowers  *
22f9fbec18Smcpowers  * Contributor(s):
23f9fbec18Smcpowers  *   Douglas Stebila <douglas@stebila.ca>, Sun Microsystems Laboratories
24f9fbec18Smcpowers  *
25f9fbec18Smcpowers  * Alternatively, the contents of this file may be used under the terms of
26f9fbec18Smcpowers  * either the GNU General Public License Version 2 or later (the "GPL"), or
27f9fbec18Smcpowers  * the GNU Lesser General Public License Version 2.1 or later (the "LGPL"),
28f9fbec18Smcpowers  * in which case the provisions of the GPL or the LGPL are applicable instead
29f9fbec18Smcpowers  * of those above. If you wish to allow use of your version of this file only
30f9fbec18Smcpowers  * under the terms of either the GPL or the LGPL, and not to allow others to
31f9fbec18Smcpowers  * use your version of this file under the terms of the MPL, indicate your
32f9fbec18Smcpowers  * decision by deleting the provisions above and replace them with the notice
33f9fbec18Smcpowers  * and other provisions required by the GPL or the LGPL. If you do not delete
34f9fbec18Smcpowers  * the provisions above, a recipient may use your version of this file under
35f9fbec18Smcpowers  * the terms of any one of the MPL, the GPL or the LGPL.
36f9fbec18Smcpowers  *
37f9fbec18Smcpowers  * ***** END LICENSE BLOCK ***** */
38f9fbec18Smcpowers /*
39f9fbec18Smcpowers  * Copyright 2007 Sun Microsystems, Inc.  All rights reserved.
40f9fbec18Smcpowers  * Use is subject to license terms.
41f9fbec18Smcpowers  *
42f9fbec18Smcpowers  * Sun elects to use this software under the MPL license.
43f9fbec18Smcpowers  */
44f9fbec18Smcpowers 
45f9fbec18Smcpowers #ifdef _KERNEL
46f9fbec18Smcpowers #include <sys/types.h>
47f9fbec18Smcpowers #include <sys/systm.h>
48f9fbec18Smcpowers #include <sys/param.h>
49f9fbec18Smcpowers #include <sys/modctl.h>
50f9fbec18Smcpowers #include <sys/ddi.h>
51f9fbec18Smcpowers #include <sys/crypto/spi.h>
52f9fbec18Smcpowers #include <sys/sysmacros.h>
53f9fbec18Smcpowers #include <sys/strsun.h>
54f9fbec18Smcpowers #include <sys/md5.h>
55f9fbec18Smcpowers #include <sys/sha1.h>
56f9fbec18Smcpowers #include <sys/sha2.h>
57f9fbec18Smcpowers #include <sys/random.h>
58f9fbec18Smcpowers #include <sys/conf.h>
59f9fbec18Smcpowers #include <sys/devops.h>
60f9fbec18Smcpowers #include <sys/sunddi.h>
61f9fbec18Smcpowers #include <sys/varargs.h>
62f9fbec18Smcpowers #include <sys/kmem.h>
63f9fbec18Smcpowers #include <sys/kstat.h>
64f9fbec18Smcpowers #include <sys/crypto/common.h>
65f9fbec18Smcpowers #else
66f9fbec18Smcpowers #include <stdio.h>
67f9fbec18Smcpowers #include <string.h>
68f9fbec18Smcpowers #include <strings.h>
69f9fbec18Smcpowers #include <assert.h>
70f9fbec18Smcpowers #include <time.h>
71f9fbec18Smcpowers #include <sys/time.h>
72f9fbec18Smcpowers #include <sys/resource.h>
73f9fbec18Smcpowers #endif /* _KERNEL */
74f9fbec18Smcpowers 
75f9fbec18Smcpowers #include "mpi.h"
76f9fbec18Smcpowers #include "mplogic.h"
77f9fbec18Smcpowers #include "mpprime.h"
78f9fbec18Smcpowers #include "ecl.h"
79f9fbec18Smcpowers #include "ecl-curve.h"
80f9fbec18Smcpowers #include "ecp.h"
81f9fbec18Smcpowers #include "ecc_impl.h"
82f9fbec18Smcpowers #include "ec.h"
83f9fbec18Smcpowers 
84f9fbec18Smcpowers #ifndef KM_SLEEP
85f9fbec18Smcpowers #define	KM_SLEEP	0
86f9fbec18Smcpowers #endif
87f9fbec18Smcpowers 
88f9fbec18Smcpowers #ifndef _KERNEL
89f9fbec18Smcpowers /* Time k repetitions of operation op. */
90f9fbec18Smcpowers #define M_TimeOperation(op, k) { \
91f9fbec18Smcpowers 	double dStart, dNow, dUserTime; \
92f9fbec18Smcpowers 	struct rusage ru; \
93f9fbec18Smcpowers 	int i; \
94f9fbec18Smcpowers 	getrusage(RUSAGE_SELF, &ru); \
95f9fbec18Smcpowers 	dStart = (double)ru.ru_utime.tv_sec+(double)ru.ru_utime.tv_usec*0.000001; \
96f9fbec18Smcpowers 	for (i = 0; i < k; i++) { \
97f9fbec18Smcpowers 		{ op; } \
98f9fbec18Smcpowers 	}; \
99f9fbec18Smcpowers 	getrusage(RUSAGE_SELF, &ru); \
100f9fbec18Smcpowers 	dNow = (double)ru.ru_utime.tv_sec+(double)ru.ru_utime.tv_usec*0.000001; \
101f9fbec18Smcpowers 	dUserTime = dNow-dStart; \
102f9fbec18Smcpowers 	if (dUserTime) printf("    %-45s k: %6i, t: %6.2f sec\n", #op, k, dUserTime); \
103f9fbec18Smcpowers }
104f9fbec18Smcpowers #else
105f9fbec18Smcpowers #define M_TimeOperation(op, k)
106f9fbec18Smcpowers #endif
107f9fbec18Smcpowers 
108f9fbec18Smcpowers /* Test curve using generic field arithmetic. */
109f9fbec18Smcpowers #define ECTEST_GENERIC_GFP(name_c, name) \
110f9fbec18Smcpowers 	printf("Testing %s using generic implementation...\n", name_c); \
111f9fbec18Smcpowers 	params = EC_GetNamedCurveParams(name, KM_SLEEP); \
112f9fbec18Smcpowers 	if (params == NULL) { \
113f9fbec18Smcpowers 			printf("  Error: could not construct params.\n"); \
114f9fbec18Smcpowers 			res = MP_NO; \
115f9fbec18Smcpowers 			goto CLEANUP; \
116f9fbec18Smcpowers 	} \
117f9fbec18Smcpowers 	ECGroup_free(group); \
118f9fbec18Smcpowers 	group = ECGroup_fromHex(params, KM_SLEEP); \
119f9fbec18Smcpowers 	if (group == NULL) { \
120f9fbec18Smcpowers 		printf("  Error: could not construct group.\n"); \
121f9fbec18Smcpowers 		res = MP_NO; \
122f9fbec18Smcpowers 		goto CLEANUP; \
123f9fbec18Smcpowers 	} \
124f9fbec18Smcpowers 	MP_CHECKOK( ectest_curve_GFp(group, ectestPrint, ectestTime, 1, KM_SLEEP) ); \
125f9fbec18Smcpowers 	printf("... okay.\n");
126f9fbec18Smcpowers 
127f9fbec18Smcpowers /* Test curve using specific field arithmetic. */
128f9fbec18Smcpowers #define ECTEST_NAMED_GFP(name_c, name) \
129f9fbec18Smcpowers 	printf("Testing %s using specific implementation...\n", name_c); \
130f9fbec18Smcpowers 	ECGroup_free(group); \
131f9fbec18Smcpowers 	group = ECGroup_fromName(name, KM_SLEEP); \
132f9fbec18Smcpowers 	if (group == NULL) { \
133f9fbec18Smcpowers 		printf("  Warning: could not construct group.\n"); \
134f9fbec18Smcpowers 		printf("... failed; continuing with remaining tests.\n"); \
135f9fbec18Smcpowers 	} else { \
136f9fbec18Smcpowers 		MP_CHECKOK( ectest_curve_GFp(group, ectestPrint, ectestTime, 0, KM_SLEEP) ); \
137f9fbec18Smcpowers 		printf("... okay.\n"); \
138f9fbec18Smcpowers 	}
139f9fbec18Smcpowers 
140f9fbec18Smcpowers /* Performs basic tests of elliptic curve cryptography over prime fields.
141f9fbec18Smcpowers  * If tests fail, then it prints an error message, aborts, and returns an
142f9fbec18Smcpowers  * error code. Otherwise, returns 0. */
143f9fbec18Smcpowers int
ectest_curve_GFp(ECGroup * group,int ectestPrint,int ectestTime,int generic,int kmflag)144f9fbec18Smcpowers ectest_curve_GFp(ECGroup *group, int ectestPrint, int ectestTime,
145f9fbec18Smcpowers 				 int generic, int kmflag)
146f9fbec18Smcpowers {
147f9fbec18Smcpowers 
148f9fbec18Smcpowers 	mp_int one, order_1, gx, gy, rx, ry, n;
149f9fbec18Smcpowers 	int size;
150f9fbec18Smcpowers 	mp_err res;
151f9fbec18Smcpowers 	char s[1000];
152f9fbec18Smcpowers 
153f9fbec18Smcpowers 	/* initialize values */
154f9fbec18Smcpowers 	MP_CHECKOK(mp_init(&one, kmflag));
155f9fbec18Smcpowers 	MP_CHECKOK(mp_init(&order_1, kmflag));
156f9fbec18Smcpowers 	MP_CHECKOK(mp_init(&gx, kmflag));
157f9fbec18Smcpowers 	MP_CHECKOK(mp_init(&gy, kmflag));
158f9fbec18Smcpowers 	MP_CHECKOK(mp_init(&rx, kmflag));
159f9fbec18Smcpowers 	MP_CHECKOK(mp_init(&ry, kmflag));
160f9fbec18Smcpowers 	MP_CHECKOK(mp_init(&n, kmflag));
161f9fbec18Smcpowers 
162f9fbec18Smcpowers 	MP_CHECKOK(mp_set_int(&one, 1));
163f9fbec18Smcpowers 	MP_CHECKOK(mp_sub(&group->order, &one, &order_1));
164f9fbec18Smcpowers 
165f9fbec18Smcpowers 	/* encode base point */
166f9fbec18Smcpowers 	if (group->meth->field_dec) {
167f9fbec18Smcpowers 		MP_CHECKOK(group->meth->field_dec(&group->genx, &gx, group->meth));
168f9fbec18Smcpowers 		MP_CHECKOK(group->meth->field_dec(&group->geny, &gy, group->meth));
169f9fbec18Smcpowers 	} else {
170f9fbec18Smcpowers 		MP_CHECKOK(mp_copy(&group->genx, &gx));
171f9fbec18Smcpowers 		MP_CHECKOK(mp_copy(&group->geny, &gy));
172f9fbec18Smcpowers 	}
173f9fbec18Smcpowers 	if (ectestPrint) {
174f9fbec18Smcpowers 		/* output base point */
175f9fbec18Smcpowers 		printf("  base point P:\n");
176f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&gx, s, 16));
177f9fbec18Smcpowers 		printf("    %s\n", s);
178f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&gy, s, 16));
179f9fbec18Smcpowers 		printf("    %s\n", s);
180f9fbec18Smcpowers 		if (group->meth->field_enc) {
181f9fbec18Smcpowers 			printf("  base point P (encoded):\n");
182f9fbec18Smcpowers 			MP_CHECKOK(mp_toradix(&group->genx, s, 16));
183f9fbec18Smcpowers 			printf("    %s\n", s);
184f9fbec18Smcpowers 			MP_CHECKOK(mp_toradix(&group->geny, s, 16));
185f9fbec18Smcpowers 			printf("    %s\n", s);
186f9fbec18Smcpowers 		}
187f9fbec18Smcpowers 	}
188f9fbec18Smcpowers 
189f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
190f9fbec18Smcpowers 	/* multiply base point by order - 1 and check for negative of base
191f9fbec18Smcpowers 	 * point */
192f9fbec18Smcpowers 	MP_CHECKOK(ec_GFp_pt_mul_aff
193f9fbec18Smcpowers 			   (&order_1, &group->genx, &group->geny, &rx, &ry, group));
194f9fbec18Smcpowers 	if (ectestPrint) {
195f9fbec18Smcpowers 		printf("  (order-1)*P (affine):\n");
196f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
197f9fbec18Smcpowers 		printf("    %s\n", s);
198f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
199f9fbec18Smcpowers 		printf("    %s\n", s);
200f9fbec18Smcpowers 	}
201f9fbec18Smcpowers 	MP_CHECKOK(group->meth->field_neg(&ry, &ry, group->meth));
202f9fbec18Smcpowers 	if ((mp_cmp(&rx, &group->genx) != 0)
203f9fbec18Smcpowers 		|| (mp_cmp(&ry, &group->geny) != 0)) {
204f9fbec18Smcpowers 		printf("  Error: invalid result (expected (- base point)).\n");
205f9fbec18Smcpowers 		res = MP_NO;
206f9fbec18Smcpowers 		goto CLEANUP;
207f9fbec18Smcpowers 	}
208f9fbec18Smcpowers #endif
209f9fbec18Smcpowers 
210f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
211f9fbec18Smcpowers 	/* multiply base point by order - 1 and check for negative of base
212f9fbec18Smcpowers 	 * point */
213f9fbec18Smcpowers 	MP_CHECKOK(ec_GFp_pt_mul_jac
214f9fbec18Smcpowers 			   (&order_1, &group->genx, &group->geny, &rx, &ry, group));
215f9fbec18Smcpowers 	if (ectestPrint) {
216f9fbec18Smcpowers 		printf("  (order-1)*P (jacobian):\n");
217f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
218f9fbec18Smcpowers 		printf("    %s\n", s);
219f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
220f9fbec18Smcpowers 		printf("    %s\n", s);
221f9fbec18Smcpowers 	}
222f9fbec18Smcpowers 	MP_CHECKOK(group->meth->field_neg(&ry, &ry, group->meth));
223f9fbec18Smcpowers 	if ((mp_cmp(&rx, &group->genx) != 0)
224f9fbec18Smcpowers 		|| (mp_cmp(&ry, &group->geny) != 0)) {
225f9fbec18Smcpowers 		printf("  Error: invalid result (expected (- base point)).\n");
226f9fbec18Smcpowers 		res = MP_NO;
227f9fbec18Smcpowers 		goto CLEANUP;
228f9fbec18Smcpowers 	}
229f9fbec18Smcpowers #endif
230f9fbec18Smcpowers 
231f9fbec18Smcpowers 	/* multiply base point by order - 1 and check for negative of base
232f9fbec18Smcpowers 	 * point */
233f9fbec18Smcpowers 	MP_CHECKOK(ECPoint_mul(group, &order_1, NULL, NULL, &rx, &ry));
234f9fbec18Smcpowers 	if (ectestPrint) {
235f9fbec18Smcpowers 		printf("  (order-1)*P (ECPoint_mul):\n");
236f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
237f9fbec18Smcpowers 		printf("    %s\n", s);
238f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
239f9fbec18Smcpowers 		printf("    %s\n", s);
240f9fbec18Smcpowers 	}
241f9fbec18Smcpowers 	MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry));
242f9fbec18Smcpowers 	if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) {
243f9fbec18Smcpowers 		printf("  Error: invalid result (expected (- base point)).\n");
244f9fbec18Smcpowers 		res = MP_NO;
245f9fbec18Smcpowers 		goto CLEANUP;
246f9fbec18Smcpowers 	}
247f9fbec18Smcpowers 
248f9fbec18Smcpowers 	/* multiply base point by order - 1 and check for negative of base
249f9fbec18Smcpowers 	 * point */
250f9fbec18Smcpowers 	MP_CHECKOK(ECPoint_mul(group, &order_1, &gx, &gy, &rx, &ry));
251f9fbec18Smcpowers 	if (ectestPrint) {
252f9fbec18Smcpowers 		printf("  (order-1)*P (ECPoint_mul):\n");
253f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
254f9fbec18Smcpowers 		printf("    %s\n", s);
255f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
256f9fbec18Smcpowers 		printf("    %s\n", s);
257f9fbec18Smcpowers 	}
258f9fbec18Smcpowers 	MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry));
259f9fbec18Smcpowers 	if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) {
260f9fbec18Smcpowers 		printf("  Error: invalid result (expected (- base point)).\n");
261f9fbec18Smcpowers 		res = MP_NO;
262f9fbec18Smcpowers 		goto CLEANUP;
263f9fbec18Smcpowers 	}
264f9fbec18Smcpowers 
265f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
266f9fbec18Smcpowers 	/* multiply base point by order and check for point at infinity */
267f9fbec18Smcpowers 	MP_CHECKOK(ec_GFp_pt_mul_aff
268f9fbec18Smcpowers 			   (&group->order, &group->genx, &group->geny, &rx, &ry,
269f9fbec18Smcpowers 				group));
270f9fbec18Smcpowers 	if (ectestPrint) {
271f9fbec18Smcpowers 		printf("  (order)*P (affine):\n");
272f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
273f9fbec18Smcpowers 		printf("    %s\n", s);
274f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
275f9fbec18Smcpowers 		printf("    %s\n", s);
276f9fbec18Smcpowers 	}
277f9fbec18Smcpowers 	if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
278f9fbec18Smcpowers 		printf("  Error: invalid result (expected point at infinity).\n");
279f9fbec18Smcpowers 		res = MP_NO;
280f9fbec18Smcpowers 		goto CLEANUP;
281f9fbec18Smcpowers 	}
282f9fbec18Smcpowers #endif
283f9fbec18Smcpowers 
284f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_JAC
285f9fbec18Smcpowers 	/* multiply base point by order and check for point at infinity */
286f9fbec18Smcpowers 	MP_CHECKOK(ec_GFp_pt_mul_jac
287f9fbec18Smcpowers 			   (&group->order, &group->genx, &group->geny, &rx, &ry,
288f9fbec18Smcpowers 				group));
289f9fbec18Smcpowers 	if (ectestPrint) {
290f9fbec18Smcpowers 		printf("  (order)*P (jacobian):\n");
291f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
292f9fbec18Smcpowers 		printf("    %s\n", s);
293f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
294f9fbec18Smcpowers 		printf("    %s\n", s);
295f9fbec18Smcpowers 	}
296f9fbec18Smcpowers 	if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
297f9fbec18Smcpowers 		printf("  Error: invalid result (expected point at infinity).\n");
298f9fbec18Smcpowers 		res = MP_NO;
299f9fbec18Smcpowers 		goto CLEANUP;
300f9fbec18Smcpowers 	}
301f9fbec18Smcpowers #endif
302f9fbec18Smcpowers 
303f9fbec18Smcpowers 	/* multiply base point by order and check for point at infinity */
304f9fbec18Smcpowers 	MP_CHECKOK(ECPoint_mul(group, &group->order, NULL, NULL, &rx, &ry));
305f9fbec18Smcpowers 	if (ectestPrint) {
306f9fbec18Smcpowers 		printf("  (order)*P (ECPoint_mul):\n");
307f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
308f9fbec18Smcpowers 		printf("    %s\n", s);
309f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
310f9fbec18Smcpowers 		printf("    %s\n", s);
311f9fbec18Smcpowers 	}
312f9fbec18Smcpowers 	if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
313f9fbec18Smcpowers 		printf("  Error: invalid result (expected point at infinity).\n");
314f9fbec18Smcpowers 		res = MP_NO;
315f9fbec18Smcpowers 		goto CLEANUP;
316f9fbec18Smcpowers 	}
317f9fbec18Smcpowers 
318f9fbec18Smcpowers 	/* multiply base point by order and check for point at infinity */
319f9fbec18Smcpowers 	MP_CHECKOK(ECPoint_mul(group, &group->order, &gx, &gy, &rx, &ry));
320f9fbec18Smcpowers 	if (ectestPrint) {
321f9fbec18Smcpowers 		printf("  (order)*P (ECPoint_mul):\n");
322f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
323f9fbec18Smcpowers 		printf("    %s\n", s);
324f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
325f9fbec18Smcpowers 		printf("    %s\n", s);
326f9fbec18Smcpowers 	}
327f9fbec18Smcpowers 	if (ec_GFp_pt_is_inf_aff(&rx, &ry) != MP_YES) {
328f9fbec18Smcpowers 		printf("  Error: invalid result (expected point at infinity).\n");
329f9fbec18Smcpowers 		res = MP_NO;
330f9fbec18Smcpowers 		goto CLEANUP;
331f9fbec18Smcpowers 	}
332f9fbec18Smcpowers 
333f9fbec18Smcpowers 	/* check that (order-1)P + (order-1)P + P == (order-1)P */
334f9fbec18Smcpowers 	MP_CHECKOK(ECPoints_mul
335f9fbec18Smcpowers 			   (group, &order_1, &order_1, &gx, &gy, &rx, &ry));
336f9fbec18Smcpowers 	MP_CHECKOK(ECPoints_mul(group, &one, &one, &rx, &ry, &rx, &ry));
337f9fbec18Smcpowers 	if (ectestPrint) {
338f9fbec18Smcpowers 		printf
339f9fbec18Smcpowers 			("  (order-1)*P + (order-1)*P + P == (order-1)*P (ECPoints_mul):\n");
340f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&rx, s, 16));
341f9fbec18Smcpowers 		printf("    %s\n", s);
342f9fbec18Smcpowers 		MP_CHECKOK(mp_toradix(&ry, s, 16));
343f9fbec18Smcpowers 		printf("    %s\n", s);
344f9fbec18Smcpowers 	}
345f9fbec18Smcpowers 	MP_CHECKOK(mp_submod(&group->meth->irr, &ry, &group->meth->irr, &ry));
346f9fbec18Smcpowers 	if ((mp_cmp(&rx, &gx) != 0) || (mp_cmp(&ry, &gy) != 0)) {
347f9fbec18Smcpowers 		printf("  Error: invalid result (expected (- base point)).\n");
348f9fbec18Smcpowers 		res = MP_NO;
349f9fbec18Smcpowers 		goto CLEANUP;
350f9fbec18Smcpowers 	}
351f9fbec18Smcpowers 
352f9fbec18Smcpowers 	/* test validate_point function */
353f9fbec18Smcpowers 	if (ECPoint_validate(group, &gx, &gy) != MP_YES) {
354f9fbec18Smcpowers 		printf("  Error: validate point on base point failed.\n");
355f9fbec18Smcpowers 		res = MP_NO;
356f9fbec18Smcpowers 		goto CLEANUP;
357f9fbec18Smcpowers 	}
358f9fbec18Smcpowers 	MP_CHECKOK(mp_add_d(&gy, 1, &ry));
359f9fbec18Smcpowers 	if (ECPoint_validate(group, &gx, &ry) != MP_NO) {
360f9fbec18Smcpowers 		printf("  Error: validate point on invalid point passed.\n");
361f9fbec18Smcpowers 		res = MP_NO;
362f9fbec18Smcpowers 		goto CLEANUP;
363f9fbec18Smcpowers 	}
364f9fbec18Smcpowers 
365f9fbec18Smcpowers 	if (ectestTime) {
366f9fbec18Smcpowers 		/* compute random scalar */
367f9fbec18Smcpowers 		size = mpl_significant_bits(&group->meth->irr);
368f9fbec18Smcpowers 		if (size < MP_OKAY) {
369f9fbec18Smcpowers 			goto CLEANUP;
370f9fbec18Smcpowers 		}
371f9fbec18Smcpowers 		MP_CHECKOK(mpp_random_size(&n, (size + ECL_BITS - 1) / ECL_BITS));
372f9fbec18Smcpowers 		MP_CHECKOK(group->meth->field_mod(&n, &n, group->meth));
373f9fbec18Smcpowers 		/* timed test */
374f9fbec18Smcpowers 		if (generic) {
375f9fbec18Smcpowers #ifdef ECL_ENABLE_GFP_PT_MUL_AFF
376f9fbec18Smcpowers 			M_TimeOperation(MP_CHECKOK
377f9fbec18Smcpowers 							(ec_GFp_pt_mul_aff
378f9fbec18Smcpowers 							 (&n, &group->genx, &group->geny, &rx, &ry,
379f9fbec18Smcpowers 							  group)), 100);
380f9fbec18Smcpowers #endif
381f9fbec18Smcpowers 			M_TimeOperation(MP_CHECKOK
382f9fbec18Smcpowers 							(ECPoint_mul(group, &n, NULL, NULL, &rx, &ry)),
383f9fbec18Smcpowers 							100);
384f9fbec18Smcpowers 			M_TimeOperation(MP_CHECKOK
385f9fbec18Smcpowers 							(ECPoints_mul
386f9fbec18Smcpowers 							 (group, &n, &n, &gx, &gy, &rx, &ry)), 100);
387f9fbec18Smcpowers 		} else {
388f9fbec18Smcpowers 			M_TimeOperation(MP_CHECKOK
389f9fbec18Smcpowers 							(ECPoint_mul(group, &n, NULL, NULL, &rx, &ry)),
390f9fbec18Smcpowers 							100);
391f9fbec18Smcpowers 			M_TimeOperation(MP_CHECKOK
392f9fbec18Smcpowers 							(ECPoint_mul(group, &n, &gx, &gy, &rx, &ry)),
393f9fbec18Smcpowers 							100);
394f9fbec18Smcpowers 			M_TimeOperation(MP_CHECKOK
395f9fbec18Smcpowers 							(ECPoints_mul
396f9fbec18Smcpowers 							 (group, &n, &n, &gx, &gy, &rx, &ry)), 100);
397f9fbec18Smcpowers 		}
398f9fbec18Smcpowers 	}
399f9fbec18Smcpowers 
400f9fbec18Smcpowers   CLEANUP:
401f9fbec18Smcpowers 	mp_clear(&one);
402f9fbec18Smcpowers 	mp_clear(&order_1);
403f9fbec18Smcpowers 	mp_clear(&gx);
404f9fbec18Smcpowers 	mp_clear(&gy);
405f9fbec18Smcpowers 	mp_clear(&rx);
406f9fbec18Smcpowers 	mp_clear(&ry);
407f9fbec18Smcpowers 	mp_clear(&n);
408f9fbec18Smcpowers 	if (res != MP_OKAY) {
409f9fbec18Smcpowers #ifdef _KERNEL
410f9fbec18Smcpowers 		printf("  Error: exiting with error value 0x%x\n", res);
411f9fbec18Smcpowers #else
412f9fbec18Smcpowers 		printf("  Error: exiting with error value %i\n", res);
413f9fbec18Smcpowers #endif
414f9fbec18Smcpowers 	}
415f9fbec18Smcpowers 	return res;
416f9fbec18Smcpowers }
417f9fbec18Smcpowers 
418f9fbec18Smcpowers /* Performs tests of elliptic curve cryptography over prime fields If
419f9fbec18Smcpowers  * tests fail, then it prints an error message, aborts, and returns an
420f9fbec18Smcpowers  * error code. Otherwise, returns 0. */
421f9fbec18Smcpowers int
ecp_test()422f9fbec18Smcpowers ecp_test()
423f9fbec18Smcpowers {
424f9fbec18Smcpowers 
425f9fbec18Smcpowers 	int ectestTime = 0;
426f9fbec18Smcpowers 	int ectestPrint = 0;
427f9fbec18Smcpowers 	int i;
428f9fbec18Smcpowers 	ECGroup *group = NULL;
429f9fbec18Smcpowers 	ECCurveParams *params = NULL;
430f9fbec18Smcpowers 	mp_err res;
431f9fbec18Smcpowers 
432f9fbec18Smcpowers 	/* generic arithmetic tests */
433f9fbec18Smcpowers 	ECTEST_GENERIC_GFP("SECP-160R1", ECCurve_SECG_PRIME_160R1);
434f9fbec18Smcpowers 
435f9fbec18Smcpowers 	/* specific arithmetic tests */
436f9fbec18Smcpowers 	ECTEST_NAMED_GFP("NIST-P192", ECCurve_NIST_P192);
437f9fbec18Smcpowers 	ECTEST_NAMED_GFP("NIST-P224", ECCurve_NIST_P224);
438f9fbec18Smcpowers 	ECTEST_NAMED_GFP("NIST-P256", ECCurve_NIST_P256);
439f9fbec18Smcpowers 	ECTEST_NAMED_GFP("NIST-P384", ECCurve_NIST_P384);
440f9fbec18Smcpowers 	ECTEST_NAMED_GFP("NIST-P521", ECCurve_NIST_P521);
441f9fbec18Smcpowers 	ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v1", ECCurve_X9_62_PRIME_192V1);
442f9fbec18Smcpowers 	ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v2", ECCurve_X9_62_PRIME_192V2);
443f9fbec18Smcpowers 	ECTEST_NAMED_GFP("ANSI X9.62 PRIME192v3", ECCurve_X9_62_PRIME_192V3);
444f9fbec18Smcpowers 	ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v1", ECCurve_X9_62_PRIME_239V1);
445f9fbec18Smcpowers 	ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v2", ECCurve_X9_62_PRIME_239V2);
446f9fbec18Smcpowers 	ECTEST_NAMED_GFP("ANSI X9.62 PRIME239v3", ECCurve_X9_62_PRIME_239V3);
447f9fbec18Smcpowers 	ECTEST_NAMED_GFP("ANSI X9.62 PRIME256v1", ECCurve_X9_62_PRIME_256V1);
448f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-112R1", ECCurve_SECG_PRIME_112R1);
449f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-112R2", ECCurve_SECG_PRIME_112R2);
450f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-128R1", ECCurve_SECG_PRIME_128R1);
451f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-128R2", ECCurve_SECG_PRIME_128R2);
452f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-160K1", ECCurve_SECG_PRIME_160K1);
453f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-160R1", ECCurve_SECG_PRIME_160R1);
454f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-160R2", ECCurve_SECG_PRIME_160R2);
455f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-192K1", ECCurve_SECG_PRIME_192K1);
456f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-192R1", ECCurve_SECG_PRIME_192R1);
457f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-224K1", ECCurve_SECG_PRIME_224K1);
458f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-224R1", ECCurve_SECG_PRIME_224R1);
459f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-256K1", ECCurve_SECG_PRIME_256K1);
460f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-256R1", ECCurve_SECG_PRIME_256R1);
461f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-384R1", ECCurve_SECG_PRIME_384R1);
462f9fbec18Smcpowers 	ECTEST_NAMED_GFP("SECP-521R1", ECCurve_SECG_PRIME_521R1);
463f9fbec18Smcpowers 	ECTEST_NAMED_GFP("WTLS-6 (112)", ECCurve_WTLS_6);
464f9fbec18Smcpowers 	ECTEST_NAMED_GFP("WTLS-7 (160)", ECCurve_WTLS_7);
465f9fbec18Smcpowers 	ECTEST_NAMED_GFP("WTLS-8 (112)", ECCurve_WTLS_8);
466f9fbec18Smcpowers 	ECTEST_NAMED_GFP("WTLS-9 (160)", ECCurve_WTLS_9);
467f9fbec18Smcpowers 	ECTEST_NAMED_GFP("WTLS-12 (224)", ECCurve_WTLS_12);
468f9fbec18Smcpowers 
469f9fbec18Smcpowers   CLEANUP:
470f9fbec18Smcpowers 	EC_FreeCurveParams(params);
471f9fbec18Smcpowers 	ECGroup_free(group);
472f9fbec18Smcpowers 	if (res != MP_OKAY) {
473f9fbec18Smcpowers #ifdef _KERNEL
474f9fbec18Smcpowers 		printf("Error: exiting with error value 0x%x\n", res);
475f9fbec18Smcpowers #else
476f9fbec18Smcpowers 		printf("Error: exiting with error value %i\n", res);
477f9fbec18Smcpowers #endif
478f9fbec18Smcpowers 	}
479f9fbec18Smcpowers 	return res;
480f9fbec18Smcpowers }
481